All verified exploits

CVE-2026-33640 Account Takeover via Email OTP Brute Force

Deterministic critical Outline Added cve-verified-cve-2026-33640

Detects Outline instances running versions 0.86.0 through 1.5.x where the email OTP login flow has no attempt limit and the rate limiter is disabled by default. The rate limiter key can also be forged via unsigned JWT cookies, enabling unrestricted brute-force of the 6-digit OTP code within its 10-minute lifetime. Successful exploitation grants full account access including documents and admin controls.

Is your app exploitable through CVE-2026-33640?

Scan your domain free